The vendor explicitly identifies these products as affected by this CVE.
- APOGEE PXC Compact (BACnet)
- APOGEE PXC Compact (P2 Ethernet)
- APOGEE PXC Modular (BACnet)
- APOGEE PXC Modular (P2 Ethernet)
- TALON TC Compact (BACnet)
- TALON TC Modular (BACnet)
- Summary
- A low privilege authenticated attacker with network access to the integrated web server could download sensitive information from the device containing user account credentials.
- Remediation
- Update to V2.8.20 or later version
